ZeroHour

CVE-2023-0749

PoC
CVSS 3.1
6.5 medium
EPSS
<1%p49
Published
()
Modified
Description

The Ocean Extra WordPress plugin before 2.1.3 does not ensure that the template to be loaded via a shortcode is actually a template, allowing any authenticated users such as subscriber to retrieve the content of arbitrary posts, such as draft, private or even password protected ones.

Vendors
oceanwp
Products
ocean extra
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.